Permissions, Privileges, and Access Controls in Storage Protect Plus Container Agent - CVE-2023-47715
Published: March 22, 2024
Vulnerability identifier: #VU87731
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-47715
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to modify data on the system.
The vulnerability exists due to application does not properly impose security restrictions. An authenticated user with read-only permissions can add or delete entries from an existing HyperVisor configuration.
Affected software
Storage Protect Plus Container Agent
Storage Protect Plus Server
Storage Protect Plus Server
How to mitigate CVE-2023-47715
Install updates from vendor's website.
Storage Protect Plus Server - update to 10.1.16.1